4 ms·
One of the co-founders here. sigstore will be a non profit / free to use service. Think Let's Encrypt for software signing. My hope is that we shift the parad
by decodebytes 5y ago
One of the co-founders here.
sigstore will be a non profit / free to use service. Think Let's Encrypt for software signing.
My hope is that we shift the paradigm so that consuming untrusted software via packages / dependencies etc becomes as unappealing as serving a website over just plain ole HTTP has now become.
In order to make that shift, open source communities require a free and easy to use service and this is what we hope sigstore will become, which is why it's a Linux Foundation project with all code being developed and maintained by a community.
- yosamino 5y agoWhat is your rationale behind this (if I understood it correctly) being a Service rather than a way of doing things ? It's becoming increasingly difficult for me to run my own code, that I am perfectly happy to sign myself, on my own devices. That might seem like a fringe case. But it shows a deeper problem: I do not trust you. I don't even know you in the first place. Yet you (well, as part of a goup) are asking me to give you more power over my devices. What is this push towards centralizing trust ? Example: Firefox extensions need to be signed now. I can't send my friends the extensions I wrote myself. There is just no way. I can't go over to their house, sit next to them, and install my self signed-root certificate, and have their version of firefox trust it. It must be signed by Mozilla: An organization that most people will never ever in their lives's interact with. That makes no sense. And not even to speak of trying to install private Root CAs into iPhones or Android devices. How does your solution empower users to own their own devices, and not have them owned by someone they are separated from by several degrees and whom they have never met ?
- schoen 5y agoThis service is more like Certificate Transparency https://certificate.transparency.dev/ https://certificate.transparency.dev/ and less like AuthentiCode or app store code signing.
- nonameiguess 5y agoDid you follow the link to the project list on Github? The actual tool for doing the signing, cosign, is just a binary you can install on your device and generate signatures and keys yourself. The "service" part of it seems to just be having your public certificate vouched for by a trusted code signing CA. I don't see anything in the tooling that requires your users to only trust that CA. If you want to sign your cert with your own CA and tell your users to trust that instead, they seemingly can do that, just as you can do that today in browsers. That you can't do it with Firefox extensions and mobile app stores is a limitation intentionally built into the distribution channel. It's not a limitation of PKI itself. iOS, Android, and Mozilla could have chosen to let users install arbitrary trusted CAs. You shouldn't dismiss all PKI based on the fact that a few vendors have chosen to implement it in a crappy way to make walled gardens. It doesn't say this on the announcement, but looking at the actual PKI service (https://github.com/sigstore/fulcio https://github.com/sigstore/fulcio), it seems to be entirely possible to self-host the service and roll your own CA.
- decodebytes 5y agoyep, you got it. And further to this, anyone could stand up their own sigstore service. In fact we expect some of the bigger oss projects to do just that.
- atonse 5y ago(Replying to gp) It’s not even true that iOS and Android don’t let you add your own private CA certs. Are there any OS’s anywhere that prohibit this? You can install your company’s internal CA certs as part of any MDM package. And products like HashiCorp’s Vault let you manage the whole CA and signing certs etc
- ChrisMarshallNY 5y agoI 100% support youse guys in this. Good on ya. I think that compromised dependency chains are a nightmare, and we're just getting started. I write Apple apps, and dread the whole provisioning thing (which they seem to change, regularly), so this is not heavy-duty at all.